Odinstaluj:
Browse Safe (HKLM-x32\...\38985_Browse Safe) (Version: 1.0 - Gratifying Apps)
Java(TM) 6 Update 30 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216030FF}) (Version: 6.0.300 - Oracle)
Zainstaluj
http://ninite.com/java-reader/
Obok frst.exe utworz plik fixlist.txt z zawartoscia:
() C:\ProgramData\f1c11deb-468d-4e28-a37d-be8513e1bc56\maintainer.exe
HKLM\...\Run: [] => [X]
HKLM-x32\...\Run: [fst_de_140] => [X]
HKLM-x32\...\Run: [BService64] => C:\Program Files (x86)\Bench\BService\1.1\bservice64.exe
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
ProxyEnable: Internet Explorer proxy is enabled.
ProxyServer: http=127.0.0.1:3128
Toolbar: HKU\S-1-5-21-1699786860-2892862594-3170324505-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Hosts: 54.235.90.58 bnbaolfhobbbokdcmfiplbokkokobjgc
CHR Plugin: (Java(TM) Platform SE 6 U30) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
CHR Extension: (Browse Safe) - C:\Users\beata\AppData\Local\Google\Chrome\User Data\Default\Extensions\bnbaolfhobbbokdcmfiplbokkokobjgc [2014-08-17]
CHR Extension: (focusbase) - C:\Users\beata\AppData\Local\Google\Chrome\User Data\Default\Extensions\oedbdopeomhfdadjfjalggcfjnfkilbn [2014-09-21]
R2 MaintainerSvc1.02.0852221; C:\ProgramData\f1c11deb-468d-4e28-a37d-be8513e1bc56\maintainer.exe [123680 2014-11-11] ()
2014-11-11 19:28 - 2014-11-11 19:30 - 00000000 ____D () C:\AdwCleaner
2014-11-02 14:23 - 2014-11-11 16:25 - 00000000 ____D () C:\ProgramData\f1c11deb-468d-4e28-a37d-be8513e1bc56
2014-10-13 19:24 - 2014-10-13 19:24 - 00896520 _____ (Elex do Brasil Participações Ltda) C:\Users\beata\Downloads\yet_another_cleaner_mat (1).exe
2014-10-13 19:23 - 2014-10-13 19:23 - 00896520 _____ (Elex do Brasil Participações Ltda) C:\Users\beata\Downloads\yet_another_cleaner_mat.exe
2014-11-11 19:30 - 2014-08-16 16:50 - 00001291 _____ () C:\Users\beata\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
EmptyTemp:
W FRST wybierz Fix.
Usun katalog C:\FRST i to wszystko.